Impact
The Export Import Menus plugin for WordPress, versions 1.9.2 and earlier, contains an unauthenticated sensitive data exposure flaw. Because any user can trigger the export functionality without authentication, sensitive information that the plugin handles may be read or downloaded. This breach compromises confidentiality by allowing an attacker to obtain data that should only be accessible to authorized users.
Affected Systems
The flaw affects the WordPress plugin Export Import Menus developed by Akshay Menariya. The vulnerability exists in all released versions up to and including 1.9.2. WordPress installations that have this plugin installed and not yet updated are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk. Because the flaw is unauthenticated, an attacker can exploit it remotely with no pre‑authentication, assuming network access to the site. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Therefore, the likelihood of exploitation depends on site exposure and attacker interest, but the potential impact is the loss of confidential data.
OpenCVE Enrichment